CyberRota Analysis
AI-GeneratedThe vulnerability lies in the embedded static RSA private key within the firmware of the Lighttpd web server, which is used for TLS termination. This exposure compromises the confidentiality and integrity of HTTPS communications, allowing attackers to decrypt traffic and potentially spoof the server. Organizations using this web server should prioritize remediation to protect sensitive data and maintain secure communications.
Original NVD Description
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.